Loading…
This event has ended. Visit the official site or create your own event on Sched.
Type: Security clear filter
Wednesday, April 22
 

10:00 CEST

Improve your resilience with cybersecurity table-top exercises
Wednesday April 22, 2026 10:00 - 11:00 CEST
This session will provide a comprehensive introduction to table-top cybersecurity exercises, focusing on their importance, design, and execution. Participants will gain insights into the benefits of conducting table-top exercises, including improved incident response readiness, enhanced communication and coordination among stakeholders, and identification of gaps in policies and procedures. Practical guidance will be provided on structuring exercises to align with organizational objectives, selecting relevant scenarios, and engaging participants effectively.
Speakers
avatar for Stefan Schörling

Stefan Schörling

Cloud Security and Infra Geek - Onevinn AB, Onevinn
Stefan Schörling has over 25 years of experience from working with Cybersecurity.

Today Stefan is helping customers to be successful with implementing and adopting Cloud Security with a focus on Azure and Microsoft 365.

For the last 15+ years he has been awarded as a Microsof... Read More →
avatar for Mattias Borg

Mattias Borg

Cyber security Researcher
Cybersecurity Researcher, Penetration Tester, and Incident Response geek - short description "like to break stuff, and then fix it sometimes"
One of the persons in the duo DefenderBoys - Defenderboys.com

With a strong focus on threat hunting within the Microsoft security ecosystem... Read More →
Wednesday April 22, 2026 10:00 - 11:00 CEST
Room 2

14:00 CEST

Mastering the Privileged Access Workstation: Secure by Design
Wednesday April 22, 2026 14:00 - 15:00 CEST
Curious about how to build a rock-solid Privileged Access Workstation (PAW) that meets today’s toughest security demands? Join us for a deep dive into the why, what, and how of PAWs - from hardened Windows configurations and ACfB to secure provisioning, network isolation, and seamless Intune management. We’ll demystify concepts like browse-up/browse-down, explore the quirks of hardware tokens, and explain why a separate Entra tenant might be your best friend. Whether you're starting from scratch or refining your setup, this session will arm you with practical insights to elevate your security posture.

Our examples will focus on the ETSI TS 103 994-1 for conforming to UK TSA regulation but the concepts are universal for virtually any sector requiring a PAW.
Speakers
avatar for Anders Ahl

Anders Ahl

Global Product Owner UEM & PAW, Ericsson
After navigating the ever-changing cosmos of technology for over three decades, orchestrating the deployment and management of devices across diverse constellations, my celestial journey took a transformative turn. Having spent 20 years as a steadfast crew member at Microsoft - charting... Read More →
avatar for Nickolaj Andersen

Nickolaj Andersen

Senior Architect EUC, Ericsson
Nickolaj specializes in Enterprise Mobility and Security, Windows deployments and automation. Additionally, he has extensive experience with planning, implementing and migrating Microsoft Endpoint Manager environments on a global scale. Nickolaj has also been awarded as PowerShell... Read More →
Wednesday April 22, 2026 14:00 - 15:00 CEST
Louis Armand OUEST

16:00 CEST

The Ransomware that never was
Wednesday April 22, 2026 16:00 - 17:00 CEST
When companies are affected by a breach, usually they contact an Incident Response provider to get help eradicating the threat actor from their environment.

This procedure generally speaking takes place when all computers and servers are encrypted and the only thing that matters is the RTO and RPO.

This session however, will look at one case where the threat actor was unable to execute their end goal.

Join this session to learn a number of hardening settings you must have in place, tips and tricks on monitoring, and last but not least the importance of end user awareness.
Speakers
avatar for Viktor Hedberg

Viktor Hedberg

Senior Technical Architect @ Truesec AB, Truesec
Security consultant with a focus on Microsoft Security either on-prem or in the cloud, and a blueteamer at heart. Viktor has worked within IT for the past 10 years always within Cyber Security. Working for public sector in Sweden for years but now as a specialist at Truesec AB focusing... Read More →
Wednesday April 22, 2026 16:00 - 17:00 CEST
Room 2
 
Thursday, April 23
 

09:50 CEST

What's next after you mitigated AITM ??
Thursday April 23, 2026 09:50 - 10:50 CEST
From a historical perspective in the scope of compromising Identitoes. we have a few waves of innovations the last 10 years. We moved from username / password to MFA. Last two years, with the adversary in the middle attacks, we need to move to more secure MFA, phishing resistant MFA. But what's next ? Think about stealing tokens from your device and reuse that on other systems.
Speakers
avatar for Erik Loef

Erik Loef

Proxsys, PROXSYS*
CTO, MSc, CEH, MVP
avatar for Kenneth van Surksum

Kenneth van Surksum

Microsoft MVP Intune, Identity and Access, Secure At Work
As a Microsoft 365 Modern Workplace consultant I help customers implement modern workplace solutions based on top of their Microsoft 365 licensing, leveraging products like Microsoft Intune, Microsoft Entra, Microsoft Defender, Exchange Online, Microsoft Teams, Microsoft SharePoint... Read More →
Thursday April 23, 2026 09:50 - 10:50 CEST
Room 1

12:00 CEST

Privileged Access Workstations - The ins and outs
Thursday April 23, 2026 12:00 - 13:00 CEST
The topic of Privileged Access Workstations (PAW) is hot again. But, many companies struggle to understand exactly what it means, how it will affect operations, and why to bother in the first place.

This session aims to remedy that, with a dive into theoretical practices regarding PAWs, and of course, live demoes of how they work with each other, and the intended administrative interfaces.

Buckle up, and get ready to gain insights into Administrative Tiering as a concept, the roles of PAWs, and how to implement them in your environment.
Speakers
avatar for Viktor Hedberg

Viktor Hedberg

Senior Technical Architect @ Truesec AB, Truesec
Security consultant with a focus on Microsoft Security either on-prem or in the cloud, and a blueteamer at heart. Viktor has worked within IT for the past 10 years always within Cyber Security. Working for public sector in Sweden for years but now as a specialist at Truesec AB focusing... Read More →
Thursday April 23, 2026 12:00 - 13:00 CEST
Room 3

12:00 CEST

Rethinking Security Prioritization in Defender: Ranking Security Risk with Tier-Based Risk Score
Thursday April 23, 2026 12:00 - 13:00 CEST
Security teams are often overwhelmed by large numbers of security recommendations in Defender, many labeled as high or critical. The real challenge is not finding risks, but deciding which ones truly matter first. This session shows how a tier-based risk analysis model can bring clarity and focus to security prioritization.

We introduce a practical approach that combines security impact and real-world consequences into a custom risk score, which is then translated into clear priority tiers (Tier 0–3). These tiers make it easier to understand urgency, align actions across teams, and focus remediation efforts where they have the highest effect.

In this session, you will learn:
* Why traditional severity ratings fail to support effective prioritization
* How to calculate risk based on impact and consequence, not just likelihood
* How Tier 0–3 prioritization simplifies decision-making and remediation planning
* How tiering helps align security priorities with business-critical assets

By the end of the session, you will understand how tier-based risk analysis reduces noise, improves consistency, and enables security teams to act faster and more confidently on the recommendations that matter most.
Speakers
avatar for Morten Knudsen

Morten Knudsen

Triple Microsoft MVP (Security, Azure, Security Copilot) | MCT | Security & Cloud Architect | Co-Founder Experts Live De, 2LINKIT
Morten is a Triple Microsoft MVP (Security, Azure, and Security Copilot), a Microsoft Certified Trainer, and holds over 17 active Microsoft certifications.

As a Cloud and Security Architect, he focuses on Azure infrastructure, Microsoft 365, automation, security, AI, and hybrid cl... Read More →
Thursday April 23, 2026 12:00 - 13:00 CEST
Room 2

14:00 CEST

M365 Defender - Custom detections everything you need to know
Thursday April 23, 2026 14:00 - 15:00 CEST
In this session we will show you everything you need to know when building custom detections in Microsoft 365 Defender. We will also walk you through several practical use cases everyone should have in their environment.
Speakers
avatar for Stefan Schörling

Stefan Schörling

Cloud Security and Infra Geek - Onevinn AB, Onevinn
Stefan Schörling has over 25 years of experience from working with Cybersecurity.

Today Stefan is helping customers to be successful with implementing and adopting Cloud Security with a focus on Azure and Microsoft 365.

For the last 15+ years he has been awarded as a Microsof... Read More →
avatar for Mattias Borg

Mattias Borg

Cyber security Researcher
Cybersecurity Researcher, Penetration Tester, and Incident Response geek - short description "like to break stuff, and then fix it sometimes"
One of the persons in the duo DefenderBoys - Defenderboys.com

With a strong focus on threat hunting within the Microsoft security ecosystem... Read More →
Thursday April 23, 2026 14:00 - 15:00 CEST
Louis Armand EST
 
Friday, April 24
 

09:00 CEST

Using LOLBins to circumvent all your security - Even in 2026
Friday April 24, 2026 09:00 - 10:00 CEST
We all read about scary 0-day exploit or CVE popping up every now and then forcing us to take action.

However, did you know that most actors use Windows, to attack Windows? Meaning the built in tools and features allowing for Living Of the Land (LOL) and their binaries (Bins). This session will showcase that an environment, protected by using EDR is still susceptible ti these types of attacks, even in Windows 11 and in the year 2026.
Speakers
avatar for Viktor Hedberg

Viktor Hedberg

Senior Technical Architect @ Truesec AB, Truesec
Security consultant with a focus on Microsoft Security either on-prem or in the cloud, and a blueteamer at heart. Viktor has worked within IT for the past 10 years always within Cyber Security. Working for public sector in Sweden for years but now as a specialist at Truesec AB focusing... Read More →
Friday April 24, 2026 09:00 - 10:00 CEST
Room 1

10:15 CEST

Top Client Hardening Tips
Friday April 24, 2026 10:15 - 11:15 CEST
In this session we will walk you through the most common threat vectors threat actors use to exploit on client devices. The session will be a mix of practical tips and demos of how to mitigate relevant threat vectors.
Speakers
avatar for Stefan Schörling

Stefan Schörling

Cloud Security and Infra Geek - Onevinn AB, Onevinn
Stefan Schörling has over 25 years of experience from working with Cybersecurity.

Today Stefan is helping customers to be successful with implementing and adopting Cloud Security with a focus on Azure and Microsoft 365.

For the last 15+ years he has been awarded as a Microsof... Read More →
avatar for Jörgen Nilsson

Jörgen Nilsson

Trusted advisor, Onevinn
Jorgen is working as a principal consultant at Onevinn in Sweden. He has been working as a consultant since 1993 with a focus on Enterprise Client Management and System Management. Involved in many projects and also a Microsoft Certified Trainer, Microsoft Security MVP and Windows... Read More →
Friday April 24, 2026 10:15 - 11:15 CEST
Room 1

13:45 CEST

Application Control in the Real World: Deep Dive into Structure, Signing, and Deployment
Friday April 24, 2026 13:45 - 14:45 CEST
Application Control for Business (ACfB) is one of the most powerful security layers in Windows, but implementing it at scale is far from trivial. In this deep dive, we’ll go beyond the basics and dissect the ACfB policy structure, explore common pitfalls (think app GUID mismatches, XML syntax quirks, and supplemental policy chaos), and uncover why the “simple” act of signing your policies can completely derail your deployment strategy.

We’ll walk through the end-to-end signing process, with special focus on Azure Trusted Signing Services, how it works, what to trust, and how to integrate it into automated pipelines without breaking your rollout. All of this will be framed in the context of Privileged Access Workstations (PAWs), but the principles apply equally to broader enterprise scenarios. We’ll also show how to scale up or peel back security layers for less restrictive environments while maintaining operational efficiency.
Expect real-world lessons, live demos, and battle-tested best practices that will help you avoid costly mistakes and build a robust ACfB implementation strategy.
Speakers
avatar for Anders Ahl

Anders Ahl

Global Product Owner UEM & PAW, Ericsson
After navigating the ever-changing cosmos of technology for over three decades, orchestrating the deployment and management of devices across diverse constellations, my celestial journey took a transformative turn. Having spent 20 years as a steadfast crew member at Microsoft - charting... Read More →
avatar for Nickolaj Andersen

Nickolaj Andersen

Senior Architect EUC, Ericsson
Nickolaj specializes in Enterprise Mobility and Security, Windows deployments and automation. Additionally, he has extensive experience with planning, implementing and migrating Microsoft Endpoint Manager environments on a global scale. Nickolaj has also been awarded as PowerShell... Read More →
Friday April 24, 2026 13:45 - 14:45 CEST
Louis Armand EST
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.